Penetration testing in Paris: what to check before you sign
If you are buying a penetration test for a company in Paris this year, finding a supplier is the easy part. Île-de-France holds most of the French offensive security market, and ANSSI now runs its own briefings out of Campus Cyber at La Défense. The awkward part is that the French rulebook you are supposed to be testing against is still unfinished, so a lot of requirements documents going out right now cite obligations that do not legally exist yet.
France has not transposed NIS 2, and it is now a court case
Member states had until 17 October 2024 to transpose NIS 2. France missed it, along with 18 others, and received a reasoned opinion from the European Commission. On 8 July 2026 the Commission referred France, Ireland, Spain and the Netherlands to the Court of Justice and asked for financial penalties: a lump sum plus daily fines until full transposition is notified.
The French vehicle is the resilience bill, which bundles NIS 2 with the CER directive and DORA. It cleared the Senate and then stalled in the National Assembly, blocked in part by Article 16 bis on lawful access, with examination pushed to the autumn session at the earliest.
For a buyer, that produces a strange gap. There is no French deadline you can put in a board pack, and there is also no scenario where the obligations go away. Testing decisions made now will be audited later against rules written in between.
ANSSI already published what it expects
The agency did not wait for parliament. At its 17 March 2026 event at Campus Cyber, ANSSI released the Référentiel Cyber France, known as ReCyF, as a working document pending transposition. It sets out the security measures aligned to NIS 2 objectives and applies a proportionality principle, so the expected effort scales with an entity's maturity and resources. ANSSI also opened voluntary pre-registration and published a tool that maps ReCyF requirements against ISO 27000-series and other frameworks.
The absence of a French law is not the absence of a French expectation.
Practical reading: write your test scope against ReCyF and your existing ISO or DORA control set, not against a statute that has no adoption date. If your provider has never heard of ReCyF, that tells you something about how closely they follow the French file. On cadence, we covered what NIS 2 actually asks of a mid-market entity separately.
PASSI is a label, not a universal requirement
PASSI is the ANSSI qualification for security audit providers. The agency published version 2.2 of the framework on 29 November 2024, introducing two qualification levels, high and substantial, aligned with the European Cybersecurity Act. ANSSI publishes the list of qualified providers, and it is short relative to the number of firms selling penetration tests in France.
It is a real signal about method and confidentiality controls. It is not a general legal requirement, and NIS 2 does not name it. Paying a qualified-provider premium on a scope that never needed qualification is one of the more common ways a French security budget disappears. We wrote the full comparison of PASSI, CREST and OSCP if you are weighing the labels, and the European price ranges if you are weighing the quotes.
Point the test where French incidents actually start
ANSSI's Panorama de la cybermenace 2025, published on 11 March 2026, counts 3,586 security events handled during the year, including 2,209 reports and 1,366 confirmed incidents. The agency singles out edge equipment as heavily targeted because of the volume of vulnerabilities affecting it, and says those compromises took up much of its incident response capacity.
That is a scoping instruction. A test aimed only at the flagship web application, with the VPN concentrator, the file transfer appliance and the exposed admin interfaces marked out of scope, is testing the part that did not cause most of last year's French incidents.
What to ask before you sign
- Which framework does the report map to. ReCyF, ISO 27001, DORA articles, or nothing. A finding not tied to a control is work your compliance team has to redo.
- Where does my data live. A Paris head office says nothing about where traffic, credentials and findings are processed. Ask for the hosting region and the sub-processor list, and read our note on EU sovereignty and the Cloud Act.
- Is my exposed edge in scope. Name the appliances, not just the applications.
- Do I actually need PASSI here. Ask the provider to explain when it is required rather than assuming it always is.
- What happens between tests. The resilience decrees will land on a schedule nobody controls. A single annual exercise leaves most of the year unevidenced.
Fleuret runs agentic pentests on EU infrastructure with reports built for the French and European frameworks buyers are actually audited against. See Fleuret in action.
Sources
- Commission calls on 19 Member States to fully transpose the NIS2 Directive, European Commission, DG CONNECT
- Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity, European Commission, 2026-07-08
- NIS 2 delayed again: France referred to the European Court of Justice, IT-Connect, 2026-07-14
- NIS 2: l'ANSSI poursuit et renforce sa dynamique d'accompagnement, ANSSI, 2026-03-17
- ReCyF: publication du référentiel d'exigences et du comparateur, Lab ANSSI
- L'ANSSI met à jour les référentiels PASSI (version 2.2) et PRIS (version 3.0), ANSSI, 2024-11-29
- Panorama de la cybermenace 2025, ANSSI / CERT-FR, 2026-03-11